1/19
This set of vocabulary flashcards covers fundamental concepts of network defense, security goals, human error taxonomies, and risk assessment frameworks as discussed in the lecture.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
NIST
A standards institution for the United States that provides recommendations and suggestions for how to properly conduct risk assessment.
Assets
The specific things being protected within an organization, such as information, services, devices, and user accounts.
Confidentiality
A core security goal that ensures only the people who should be able to see specific information are able to see it.
Integrity
A security goal dedicated to making sure information hasn't been maliciously altered on its way to the user.
Availability
A core aspect of security focused on ensuring that systems are functional and usable for their designed purposes.
Authentication
The process of proving that a user is who they claim to be.
Authenticity
The assurance that a resource, such as a website, is genuine and is truly what it says it is.
Accountability
The practice of keeping a record of everything that happened in a system to facilitate future audits.
James Reason
The person credited with the taxonomy of human errors classified as slips, lapses, and mistakes.
Slips
A form of human error where the user has the right intention but fails to execute the action correctly, such as typing a wrong IP address.
Lapses
A type of human error where a user forgets to perform a necessary action, such as failing to turn security functionality back on after production.
Mistakes
Errors of intent where a user has a fundamental misunderstanding of what they are supposed to be doing, leading to a wrong plan.
Threat Events
Specific occurrences that can cause harm to assets, including phishing messages, malware, misconfigurations, floods, and disk failures.
Vulnerability
A weakness in defense, such as insufficient authentication, unpatched services, or a firewall that is too permissive.
Risk Formula
A simple teaching formula where risk is determined by: Impact×Likelihood.
Attack Surface
The total exposure or entry points to a network that an administrator must defend or attempt to reduce.
Predisposing Condition
A contextual amplifier on the harm a vulnerability can cause, such as a system being located in an environment prone to flooding.
Identify, Protect, Detect, Respond, Recover, Govern
The six functions or pillars that comprise the NIST Cybersecurity Framework.
IETF
The organization that comes up with RFCs which define various protocols at the internet level.
IEEE
The organization responsible for standardizing Ethernet, LAN, and WiFi controls.